PandwaRF Demo: Assess the Security of Your Home Alarm Systems

PandwaRF Demo: Assess the Security of Your Home Alarm Systems


Hello everybody
Today in this video I will show you the brute force attack with a ComThings device, the
PandwaRF. First for the setup we have a PandwaRF, a
smartphone with the Android application and an alarm. This alarm is a classical GSM system to protect
houses with several sensors, to detect movement or door opening. We have the remote control of the system
and we can arm it. The sensors detect intrusion and the alarm
reacts. The PandwaRF is already connected to the application
and we select the alarm in our list. We see that all the parameters are set: frequency,
data rate, modulation, function mask… We also have an estimated duration for the
brute force of 8 minutes and 47 seconds. To shorten this time we just reduce the interval
around the known value of this alarm. We arm the system and we launch the brute
force attack. It is in progress, the led turns red. And the system is now disarmed, the lock is
open. No reaction anymore. We switch to arm and we launch the attack. The system is rearmed. The brute force attack was a success. Now I will do a second demo with another alarm. It’s a classical door alarm. We arm it, wait until it is armed… Now it is armed. Like the last time, we select the alarm in
our list and we can launch the brute force attack. We have the signal, we wait a little bit… And the system is armed. We saw in this video that the PandwaRF is
able to brute force different alarms. Thanks for watching!

2 Replies to “PandwaRF Demo: Assess the Security of Your Home Alarm Systems”

  1. Hi , which software version did you use? I've tried 1.3.7 , and is different from the one you presented here .On 1.3.7 version there is only 1 option for this kind of scanning : Type: Home Alarm , Brand: Forecum , Model: Model_1 , Function: Thunder , Arm ,Disarm , Bell . That's all .I own a PandaRF Big . Hardware Revision E

Leave a Reply

Your email address will not be published. Required fields are marked *